Third Party Index

Snapshot 64810

Document
Trust center
URL
https://www.squivr.com/trust
Fetched
HTTP status
200
Content type
text/html;charset=utf-8
Fetch mode
static
Size
277789 bytes
SHA-256 (raw)
12cbe7e1e725777ecc269e7f2fbe199a30825e254e73a7adb856ad36744a368f
SHA-256 (normalized text)
7c4c346275ef3357d058825533450ac8fa9aa52563d1907400d023c8bde3eae6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

0
Squivr Trust Center
Your data never leaves
Salesforce
Squivr is built 100% natively on the Salesforce platform. No external hosting, no third-party integrations, no client downloads. Just the enterprise-grade security you already trust.
Security document (PDF) Data processing agreement
Data never leaves Salesforce No third-party integrations No client downloads
0%
Salesforce native
0
External data stores
RBAC
Role-based access control
ISV
Salesforce partner
Core security pillars
Security built on a
foundation you already trust
Because Squivr runs entirely within Salesforce, every security control Salesforce provides is inherited automatically. No gaps, no handoffs, and no additional risk surface.
No external hosting
All data remains under your direct control within the Salesforce instance you already manage and trust. No replication, no sync, no exposure.
Inherited enterprise security
Squivr inherits Salesforce's physical infrastructure protections, encryption at rest and in transit, identity and access management, and continuous compliance monitoring.
No third-party integrations
No third-party integrations are required for core functionality. This reduces exposure and dramatically simplifies your organization's risk surface.
Role-based access control
Squivr respects and reinforces your existing Salesforce security model, including role-based access, native sharing rules, permission sets, and multi-factor authentication.
Full auditability
Since all activity remains within Salesforce, admins maintain complete visibility using standard Salesforce audit logs, permission sets, and admin tools.
Compliance ready
Because Squivr is 100% native to Salesforce, your org automatically inherits Salesforce's SOC 2, ISO 27001, and FedRAMP compliance. No separate certification needed.
Your Salesforce org Your records Squivr Your users Data moves between these three. It never crosses the boundary.
Squivr is installed inside your Salesforce org. It is a native package, not a connected service. Your records, the application, and your users share one boundary, and nothing is copied to a Squivr-operated environment, because no such environment exists.
Squivr sits inside the perimeter you already control Installed from AppExchange as a native package. It runs on your org's permissions, your sharing rules, and your MFA policy. There is no Squivr server, no Squivr database, and no Squivr login.
Because there is nothing outside the boundary, four categories of risk never arise:
No external hosting No second copy of your data living somewhere you cannot audit, breach-test, or subpoena.
No third-party APIs No sub-processor chain to review, and no vendor outage that can take Squivr down independently.
No client downloads Nothing on the endpoint to patch, version, or whitelist. Squivr runs in the Lightning UI your team already loads.
No data replication No sync window where records drift out of date, and no stale export sitting in a forgotten bucket.
Salesforce-native architecture
The security model that
eliminates the risk
A key pillar of Squivr's security is our Salesforce-native architecture, which provides a strong foundation for data protection, compliance, and trust. Since our solution operates entirely within the Salesforce platform, your data never leaves your Salesforce environment.
No external hosting or data replication. All data stays in your Salesforce instance.
Inherited security controls including physical infrastructure protections
Encryption at rest and in transit via the Salesforce platform
Identity and access management built in from day one
SOC 2, ISO 27001, and FedRAMP compliance inherited automatically through Salesforce
No third-party integrations required for any core functionality
Built on Salesforce Native AppExchange ISV partner
Web application security
Security-aware API endpoints, content security policies, strict data validation, and Salesforce's built-in WAF protection.
Platform integrity
Salesforce's web application firewall detects and blocks malicious traffic. Squivr inherits this protection automatically.
Data access controls
RBAC and MFA ensure secure user access. Your Salesforce admin controls all permissions, logging, and access to Squivr through native Salesforce tools.
Lightning Design System
Squivr uses the Lightning Design System so it looks and feels exactly like native Salesforce, reducing user friction and training overhead.
Your user, in the Lightning UI The same browser session they already use for Salesforce. Nothing extra is installed.
Browser
Authenticated request
Your Salesforce org
Network and WAF Traffic filtering, DDoS protection, and intrusion monitoring at the platform edge.
Salesforce
Identity and MFA Authentication, session control, and multi-factor enforcement before any code runs.
Salesforce
Permissions and sharing Profiles, permission sets, and sharing rules decide which records are visible.
Your admin
Application tier
Squivr Native managed package. Apex and Lightning components running on the platform.
Your records Standard and custom Salesforce objects, in the org you already administer.
Squivr executes here, against records that are already in your org. There is no step after this one.
A request crosses four controls before Squivr runs. Three are enforced by Salesforce and one by your own administrator. Because Squivr is a native package rather than a connected service, it sits at the end of that path instead of alongside it, so every control your organization has already reviewed applies to it unchanged.
Shared responsibility model
Who is responsible
for what
Select any row to see how responsibility is shared across Squivr, Salesforce, and your team.
Security area	Squivr	Salesforce	Customer
Privacy and compliance
Compliant with the
standards that matter
The Squivr application is listed publicly on AppExchange and is compliant with the same privacy and compliance requirements as Salesforce. We follow all Salesforce ISV best practices and security policies.
SOC 2 (via Salesforce)
Squivr does not hold its own SOC 2 certification. Because we are 100% native to Salesforce, your org inherits Salesforce's SOC 2 compliance automatically.
ISO 27001 (via Salesforce)
Squivr does not hold its own ISO 27001 certification. Running natively on Salesforce means your org benefits from Salesforce's ISO 27001 program without any additional burden.
FedRAMP (via Salesforce)
Squivr does not hold its own FedRAMP authorization. For Government Cloud deployments, your org inherits Salesforce's FedRAMP coverage directly through the native platform.
Salesforce resources
Verify directly with Salesforce
Salesforce Compliance Center Full list of certifications and frameworks Salesforce Trust Portal Real-time system status and security info AppExchange listing Squivr's official AppExchange profile Security document (PDF) Full Squivr security overview Data processing agreement For your legal and security teams
Admin control
Your admin stays
in full control
Your Salesforce administrator controls the permissions, logging, and access to the Squivr application through native Salesforce functionality. Squivr has the same availability as your Salesforce instance.
Permissions managed through Salesforce permission sets and profiles
Full audit logging via standard Salesforce audit tools
Availability tied directly to your Salesforce instance uptime
Access controls enforced at the Salesforce platform level
No separate admin portal and no separate credentials to manage
Frequently asked questions
No. All Squivr data is stored and processed entirely within your Salesforce org. There are zero external data stores or third-party databases involved at any point.
Yes. Since Squivr uses native Salesforce permission sets, access can be revoked instantly through your existing admin tools with no extra steps required.
Uninstalling Squivr removes the app from your org. Because data is stored as standard Salesforce objects within your org, you retain full ownership and can export or delete it using standard Salesforce tools.
Yes. Squivr inherits Salesforce's MFA enforcement, so if MFA is enabled in your org it applies to Squivr automatically. No separate configuration is required.
Squivr supports Salesforce Government Cloud deployments, inheriting FedRAMP compliance for organizations that require it. Contact us at info@squivr.com for details.
Data never leaves Salesforce
All Squivr data is stored and processed entirely within your Salesforce org. Zero external data stores.
No third-party web services
Core functionality requires no external API calls or third-party service dependencies.
No client downloads or plug-ins
Squivr runs entirely in the browser via Salesforce Lightning. Nothing to install and nothing to update.
Continuous security updates
Squivr benefits from Salesforce's continuous security updates, active threat monitoring, and compliance maintenance.
Connect with Squivr
Get in touch with
our team
Questions about security, compliance, or our data processing agreement? We are here to help.
Squivr, Denver, Colorado
Email us
info@squivr.com
General enquiries and security questions
AppExchange
Get Squivr on AppExchange
View our official listing
Security document
Download full security overview
PDF, share with your security team
Data processing agreement
Download our DPA
PDF, share with your legal team
Review our security documentation
Download our full security document and data processing agreement to share with your security and legal teams.
Security document (PDF) Data processing agreement
Questions? Email info@squivr.com